Potential RipZip Attack on Startup Folder

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "File Created or Modified" AND ((FILENAME contains "\Microsoft\Windows\Start Menu\Programs\Startup" AND FILENAME contains ".lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D}") OR (OBJECTNAME contains "\Microsoft\Windows\Start Menu\Programs\Startup" AND OBJECTNAME contains ".lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D}")) AND PROCESSNAME endswith "\explorer.exe" select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.OBJECTNAME,Action1.FILENAME,Action1.PROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Greg (rule)